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DETAILED ACTION 

1 . Claims 1-20 remain for examination. Tine correspondence filed 2/29/08 amended claims 1 , 7, 
13, and 20. 

Response to Arguments 

2. Applicant's arguments filed 2/29/08 have been fully considered but they are not persuasive. 
Examiner maintains that the P-synch references describing version 6.2 of that product may constitute 
prior art based on the arguments made in the previous Office Action establishing that the documents 
in question are reprints of other documents published, and reserves the right to reuse those 
reference(s) in subsequent rejections as may be warranted. 

3. With regards to the amended claim limitations, it is observed that Applicant appears to 
misunderstand the functionality disclosed by P-Synch. For example, P-Synch [version 4.2] clearly 
discloses wherein a user can invoke a GUI, either through a Windows application or a web browser, 
through which a user may interactively select which passwords one wishes to change and to execute 
the appropriate programs to do so (pages 13-15, but particularly "WWW GUI", 1^' paragraph). Thus, 
it is once again observed that the various limitations added to the claims are nevertheless disclosed 
or suggested by the full P-Synch reference(s), and the rejections will be rewritten to incorporate the 
new details. However, in the course of searching the P-synch references, the Examiner discovered 
an error made in the previous Office Action regarding how the P-Synch product version 4.2 stores 
passwords; accordingly, the rejections under 35 USC 102(b) have been withdrawn, to be replaced by 
new rejections under 35 USC 103(a). Examiner apologizes for the error, and has included the full 
text of all pertinent P-Synch manuals for Applicant's perusal. 
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Claim Objections 

4. Applicant is advised that should claims 1 , 7 & 13 be found allowable, claims 3, 8, & 14 will be 
objected to under 37 CFR 1 .75 as being a substantial duplicate thereof. When two claims in an 
application are duplicates or else are so close in content that they both cover the same thing, despite 
a slight difference in wording, it is proper after allowing one claim to object to the other as being a 
substantial duplicate of the allowed claim. See MPEP § 706.03(k). It is observed that the 
Independent claims have been amended to include all the limitations of the objected claims; thus the 
objected claims fail to further limit the claimed invention. 

5. Claim 20 Is objected to because of the following informalities: line Item [II] recites the limitation 
"user profile tables" twice as separate elements of the same list. Appropriate correction to remove 
the redundancy is required. 

Claim Rejections - 35 USC § 103 

6. The text of those sections of Title 35, U.S. Code not included in this action can be found In a 
prior Office action. 

7. Claims 1-20 are rejected under 35 U.S.C. 103(a) as being unpatentable over the P-Synch 

Installation and Administration Guide (Software version 4.2, Document Version 4.50, last changed 
6/1/2000; hereinafter "P-Synch") in view of "Using Privacy Features" web page (hereinafter, "Mozllla"). 

Regarding claim 1 : 

P-Synch discloses a tool for managing passwords, comprising: storage for a plurality of current 
passwords for a plurality of respective applications (password history, pages 33 & 34), and for each of 
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said applications: a description of the application (page 27, "3.1.2 Target system information"), a 
description of the password type for the application (Ibid); previous passwords for the application 
(page 7, "Password history"), and a Uniform Resource Locator for the application (page 27, "3.1 .2 
Target system information"; cf. page 28, Table 3.1); means for displaying a reminder to change one 
or more passwords (page 14, "Expiry detection and password aging"); and a script for simulating 
keystroke entries, or running an executable program, to automatically perform a password change in 
said respective applications for said current passwords of said reminder (Ibid, and pages 13-14) 
wherein the tool displays a list of the passwords, a description of the computer applications, a 
description of the procedure for changing the password, and a graphical user interface (pages 13-15, 
"WWW GUI" and "Windows GUI"; pages 54-55, "HOST statement" and Table 4.1 ; pages 69-70, 
disclosing the means by which this information is displayed; pages 246-247, Tables 8.6 and 8.7; while 
further observing that as the scripts are by definition a description of the procedure for changing the 
password, the ability to display the scripts for at least the purpose of editing them reads on that 
limitation); and a user uses the graphical user interface to invoke the scripts needed to change the 
passwords (pages 13-15, "WWW GUI" and "Windows GUI"), and the script tests proposed new 
passwords to determine if said proposed new passwords meet a defined criteria, and the script 
changes a password only if the proposed new password meets the defined criteria (page 7, 
"Password strength rules"; page 11, "Enforcing strong password rules..."). 

It is observed that the password storage area for holding previous passwords cited above is 
not used to store current passwords (page 60), although this is not to say that current passwords 
cannot be stored somewhere within the P-Synch tool, as knowledge of a current password is still 
required for the P-Synch scripts to function correctly (e.g. page 127, "Verify" bullet point). 
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However, it is observed tliat at least one embodiment of P-Synch is a web application, wherein a 
WWW browser is a required component of the overall P-Synch tool to change one's passwords on 
the web (e.g. page 13, "WWW GUI"). Mozilla discloses the existence of a web browser comprising a 
password manager tool with storage for a user's current passwords, as well as the ability to view 
them (Mozilla, pages 5-8, "Using the Password Manager". It would have been obvious to one of 
ordinary skill in the art at the time of the invention to use the Mozilla web browser with the Password 
Manager component as the web browser component of the P-Synch tool, as the substitution of the 
Mozilla web browser in lieu of the generic web browser disclosed by P-Synch would have yielded 
predictable results to one of ordinary skill in the art at the time of the invention. 

Regarding claims 7 and 13: 

P-Synch discloses a method and program storage device comprising: accumulating a set of 
passwords in a password management facility, each of said passwords being associated with a 
computer application having a password change procedure (pages 13-15, "2.2.1 User Password 
Changes"); storing in the password management facility, for each of said applications: a description of 
the application (page 27, "3.1.2 Target system information"), a description of the password type for 
the application (Ibid); previous passwords for the application (page 7, "Password history"), and a 
Uniform Resource Locator for the application (page 27, "3.1 .2. Target system information"; cf. page 
28, Table 3.1 ); providing the password management facility with a set of scripts to operate the 
password change procedures of the associated applications (pages 13-15); and a user invoking the 
password management facility (Ibid: "With a WWW GUI, users change their passwords from their 
browser", etc.), said facility, when invoked, displaying a list of the passwords, a description of the 
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computer applications, a description of a procedure for changing the password, and a graphical user 
interface (pages 13-15, "WWW GUI" and "Windows GUI"; pages 54-55, "HOST statement" and Table 
4.1; pages 69-70, the means to display the information; pages 246-247, Tables 8.6 and 8.7; while 
further observing that as the scripts are by definition a description of the procedure for changing the 
password, the ability to display the scripts for at least the purpose of editing them reads on that 
limitation); and using said graphical user interface to invoke or activate the scripts needed to change 
the passwords (pages 13-15, Ibid), including the steps of the scripts testing proposed new passwords 
to determine if said proposed new passwords meet a defined criteria, and the scripts changing a 
password only if the proposed new password meets the defined criteria (page 7, "Password strength 
rules"; page 11, "Enforcing strong password rules..."). 

It is observed that the password storage area for holding previous passwords cited above is 
not used to store current passwords (page 60), although this is not to say that current passwords 
cannot be stored somewhere within the P-Synch system, as knowledge of a current password is still 
required for the P-Synch scripts to function correctly (e.g. page 127, "Verify" bullet point). 
However, it is observed that at least one embodiment of P-Synch is a web application, wherein a 
WWW browser is a required component of the overall P-Synch tool to change one's passwords on 
the web (e.g. page 13, "WWW GUI"). Mozilla discloses the existence of a web browser comprising a 
password manager tool with storage for a user's current passwords, as well as the ability to view 
them (Mozilla, pages 5-8, "Using the Password Manager". It would have been obvious to one of 
ordinary skill in the art at the time of the invention to use the Mozilla web browser with the Password 
Manager component as the web browser component of the P-Synch system, as the substitution of 
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the Mozilla web browser in lieu of the generic web browser disclosed by P-Synch would have yielded 
predictable results to one of ordinary skill in the art at the time of the invention. 

Regarding claims 2, 11, and 17: 

P-Synch further discloses wherein the applications are selected from the group including 
workstation applications, legacy host applications, server applications, and networked applications 
(Table 3.1 on page 28). 

Regarding claim 3: 

P-Synch further discloses means for displaying a list of passwords (page 49, "4.3.1 . 
Overview") and means for displaying a graphical user interface for invoking the script to change 
passwords (pages 13-15). 

Regarding claims 4, 9, and 15: 

P-Synch further discloses wherein the graphical user interface includes a series of activatable 
display elements, each display element being shown adjacent to one of the passwords to invoke 
script for changing said one password (pages 13-15). 

Regarding claim 5: 

P-Synch further discloses wherein at least some of the applications include a password 
change form and require a series of actions to get to the password change form, and the script 
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includes means to perform said series of actions to get to tlie password change form (e.g. the sample 
script on pages 192-193). 

Regarding claims 6, 12, and 18: 

P-Synch further discloses wherein the passwords are encrypted in said storage (pages 33 and 

34, bullet point "hist\"). 

Regarding claims 8 and 14: 

P-Synch further discloses accessing the password management facility (pages 13-15); said 
password management facility displaying a list of passwords and a graphical user interface for 
invoking the scripts (Ibid); and using said graphical user interface to activate the scripts to change the 
passwords (Ibid). Per claim 14, P-Synch further discloses wherein the scripts test proposed new 
passwords to determine if said proposed new passwords meet a defined criteria, and the scripts 
change a password only if the proposed new password meets the defined criteria (page 7, "Password 
strength rules"). 
Regarding claims 10 and 16: 

P-Synch further discloses wherein each of the scripts simulates a set of keystroke entries or an 
executable program to change the password for one of the applications (Telnet scripts and Native 
APIs, respectively, on pages 13-15; cf. the sample scripts on pages 192-193). 
Regarding claim 19: 

P-Synch further discloses wherein the defined criteria are based on data from a user table (the 
user's password history table, pages 33 and 34). 
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Regarding claim 20: 

P-Synch further discloses displaying user prompts to obtain information from the user when a 
script or code is invoked to change one of the passwords (pages 13-15); encrypting all of the data 
stored in the facility (pages 33 & 34, bullet point "hist\"; cf. pages 346-347); and providing different 
users with different degrees of access (Help-desk users vs. end-users: see page 1 1 , the third and 
fourth bullet points); the script, based on a user identification, queries an employee table to determine 
an employee class associated with the user identification (page 207); and said criteria include [i] a 
proposed new password differs from a current password by a given number of characters (page 59, 
see the rule designated "mincharschanged=N"), [ii] criteria based on data from user tables, user 
profile tables, and user history tables (page 7, "Password history"; page 36, line item #6; page 224, 
"End-user interface"); and [iii] the user belongs to a certain class of employees (pages 35-36, and 
207). 

Conclusion 

8. The prior art made of record and not relied upon is considered pertinent to applicant's 
disclosure: 

• Excerpts from the P-Synch Installation Guide, version 6.2, obtained from the Internet Archive 
and known to be published prior to the effective priority date of the instant application, which 
provides a better illustration of the WWW GUI of the prior art invention as well as further 
disclosing or at least suggesting that employee information may be used to influence the 
behavior of the P-Synch tool 

• U.S. Patent 7,353,536 to Morris et al. 

• U.S. Patent 7,275,258 to Arbab et al. 
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• U.S. Patent 7,272,722 to Legros et al. 
9. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set 
forth in 37 CFR 1.136(a). 

A shortened statutory period for reply to this final action is set to expire THREE MONTHS from 
the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing 
date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH 
shortened statutory period, then the shortened statutory period will expire on the date the advisory 
action is mailed, and any extension fee pursuant to 37 CFR 1 .136(a) will be calculated from the 
mailing date of the advisory action. In no event, however, will the statutory period for reply expire 
later than SIX MONTHS from the mailing date of this final action. 

Any inquiry concerning this communication or earlier communications from the examiner 
should be directed to Thomas Gyorfi whose telephone number is (571 )272-3849. The examiner can 
normally be reached on 8:30am - 5:00pm Monday - Friday. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, 
Kim Vu can be reached on (571 ) 272-3859. The fax phone number for the organization where this 
application or proceeding is assigned is 571-273-8300. 
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Information regarding tlie status of an application may be obtained from the Patent Application 
Information Retrieval (PAIR) system. Status information for published applications may be obtained 
from either Private PAIR or Public PAIR. Status information for unpublished applications is available 
through Private PAIR only. For more information about the PAIR system, see http://pair- 
direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the 
Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information system, call 800- 
786-9199 (IN USA OR CANADA) or 571-272-1000. 
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4/28/08 
/KIMYEN VU/ 

Supervisory Patent Examiner, Art Unit 2135 



